The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Th3H4ck hacked hundreds of VB forums over the last two days.
Th3H4ck Has hacked hundreds of VB forums over the last few days, what is the exploit and are we working on a fix???
Just google Th3H4ck |
#2
|
|||
|
|||
Yeah I saw he joined today and used my Spam-O-Matic features to get rid of him but I would really like to know how he signed up as an Admin?
|
#3
|
|||
|
|||
Did you get an IP or any information as to what he is doing once he's in.
|
#4
|
|||
|
|||
Looks like a bot attack to me.
It relates to this article http://www.vbulletin.com/forum/forum...-1-vbulletin-5 Apache Log below: 178.33.229.22 - - [05/Sep/2013:10:10:37 +0100] "GET /forum/core/install/upgrade.php HTTP/1.1" 404 613 "-" "-" 178.33.229.22 - - [05/Sep/2013:10:10:38 +0100] "GET /forum/install/upgrade.php HTTP/1.1" 404 613 "-" "-" 178.33.229.22 - - [05/Sep/2013:10:10:39 +0100] "GET /forums/core/install/upgrade.php HTTP/1.1" 404 613 "-" "-" 178.33.229.22 - - [05/Sep/2013:10:10:39 +0100] "GET /forums/install/upgrade.php HTTP/1.1" 404 613 "-" "-" 178.33.229.22 - - [05/Sep/2013:10:10:40 +0100] "GET /core/install/upgrade.php HTTP/1.1" 404 613 "-" "-" 178.33.229.22 - - [05/Sep/2013:10:10:41 +0100] "GET /install/upgrade.php HTTP/1.1" 200 13394 "-" "-" 66.96.183.79 - - [05/Sep/2013:10:10:45 +0100] "POST /install/upgrade.php HTTP/1.1" 200 279 "-" "-" |
#5
|
|||
|
|||
Do we just delete the entire install folder?
|
#6
|
|||
|
|||
That's what it says.
|
#7
|
|||
|
|||
He signed up twice on my forum as admin. I have deleted the install folder. I dont know what else to do or what if anything he did to my forum.
|
#8
|
||||
|
||||
If you want to see what he did on your site, go to Admincp > Statistics & Logs > Control Panel Log. You will see if he added a plugin or accessed the templates, etc.
DELETE YOUR INSTALL DIRECTORY!!! |
Благодарность от: | ||
CAG CheechDogg |
#9
|
|||
|
|||
I was a victim of this also. Check my thread. If you guys haven't already you need to check the database and your templates. On my forum they put iframes in the footer of all my templates.
I had 8 Administrators in the admin group with the same name. However, one admin account was just a "." |
#10
|
|||
|
|||
IP addy 180.216.122.253 and I checked my Control Panel and I don't see anything logged for the user so it looks like he just signed up and that was it. I am almost 100% certain I deleted my install folder after the initial install a year ago.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|